Molecule on the AWS Cloud

Quick Start Reference Deployment

QS

September 2020
Ryan Vanderwerf - Partner Solutions Architect, Sean Williams - Partner Solutions Architect, Andrew Glenn - Partner Solutions Architect, Dave May - Partner Solutions Architect

Visit our GitHub repository for source files and to post feedback, report bugs, or submit feature ideas for this Quick Start.

This Quick Start was created by Dell Boomi in collaboration with Amazon Web Services (AWS). Quick Starts are automated reference deployments that use AWS CloudFormation templates to deploy key technologies on AWS, following AWS best practices.

Overview

This Quick Start reference deployment guide provides step-by-step instructions for deploying Molecule on the AWS Cloud.

This Quick Start is for users who are looking for an integration platform as a service (iPaaS) that can be hosted on AWS. This Quick Start enables you to deploy a Dell Boomi Molecule cluster on AWS and administer it through the Dell Boomi AtomSphere platform.

Amazon may share user-deployment information with the AWS Partner that collaborated with AWS on the Quick Start.

Molecule on AWS

Dell Boomi service is a minimal-code, cloud-based iPaaS that enables customers to design, deploy, manage, and govern all of their data across their hybrid and software as a service (SaaS) applications by connecting and integrating external application data with AWS services such as Amazon Simple Storage Service (Amazon S3), Amazon Simple Notification Service (Amazon SNS), Amazon Relational Database Service (Amazon RDS), and Amazon Redshift using Dell Boomi’s point-and-click graphical interface.

The Dell Boomi Molecule is a single-tenant, clustered runtime that runs separately from the platform, enabling multiple processes to run concurrently. The enterprise-grade version of a Boomi Atom runtime, the Boomi Molecule can be deployed across multiple servers to enhance load balancing and ensure high availability for mission-critical integration processes.

AWS costs

You are responsible for the cost of the AWS services and any third-party licenses used while running this Quick Start. There is no additional cost for using the Quick Start.

The AWS CloudFormation templates for Quick Starts include configuration parameters that you can customize. Some of the settings, such as the instance type, affect the cost of deployment. For cost estimates, see the pricing pages for each AWS service you use. Prices are subject to change.

After you deploy the Quick Start, create AWS Cost and Usage Reports to deliver billing metrics to an Amazon Simple Storage Service (Amazon S3) bucket in your account. These reports provide cost estimates based on usage throughout each month and aggregate the data at the end of the month. For more information, see What are AWS Cost and Usage Reports?

Software licenses

This deployment requires a Dell Boomi Molecule Enterprise license.

Architecture

Deploying this Quick Start for a new virtual private cloud (VPC) with default parameters builds the following Molecule environment in the AWS Cloud.

Deploying this Quick Start for a new virtual private cloud (VPC) with default parameters builds the following Dell Boomi environment in the AWS Cloud.

image
Figure 1. Quick Start architecture for Molecule on AWS

The Quick Start sets up the following:

  • A highly available architecture that spans two Availability Zones.*

  • A VPC configured with public and private subnets according to AWS best practices, to provide you with your own virtual network on AWS.*

  • An Application Load Balancer.

  • In the public subnets:

    • Managed NAT gateways to allow outbound internet access for resources in the private subnets.*

    • A Linux bastion host in an Auto Scaling group to allow inbound Secure Shell (SSH) access to Amazon Elastic Compute Cloud (Amazon EC2) instances in public and private subnets, with Amazon CloudWatch for monitoring.

  • In the private subnets:

    • Four Amazon EC2 instances with the Dell Boomi Molecule software installed, two in each Availability Zone.

    • Amazon Elastic File System (Amazon EFS) deployed in the Region. Two Amazon EFS mount points are created also, one in each Availability Zone.

*The template that deploys the Quick Start into an existing VPC skips the components marked by asterisks and prompts you for your existing VPC configuration.

Planning the deployment

Specialized knowledge

This deployment requires a moderate level of familiarity with AWS services. If you’re new to AWS, see Getting Started Resource Center and AWS Training and Certification. These sites provide materials for learning how to design, deploy, and operate your infrastructure and applications on the AWS Cloud.

This Quick Start assumes familiarity with basic concepts of networking, bastion hosts, volume sizing, and compute performance. It also assumes familiarity with the Dell Boomi variables that are required when deploying a Molecule cluster. These variables include Molecule Name, Local Path, Local Temp Path, Account Id, Account Name, and Account Password. If you don’t have have an Account Name or Password, you can enter an installation token provided by your system administrator into the Boomi MFA install token field.

If you are an administrator, see the following sections of this guide for help creating an installation token and API token:

This Quick Start follows the patterns for Unattended Dell Boomi Molecule deployments found in the Dell Boomi documentation. See Unattended installation of an Atom, Molecule, or Atom Cloud.

AWS account

If you don’t already have an AWS account, create one at https://aws.amazon.com by following the on-screen instructions. Part of the sign-up process involves receiving a phone call and entering a PIN using the phone keypad.

Your AWS account is automatically signed up for all AWS services. You are charged only for the services you use.

Technical requirements

Before you launch the Quick Start, review the following information and ensure that your account is properly configured. Otherwise, deployment might fail.

Resource quotas

If necessary, request service quota increases for the following resources. You might need to request increases if your existing deployment currently uses these resources and if this Quick Start deployment could result in exceeding the default quotas. The Service Quotas console displays your usage and quotas for some aspects of some services. For more information, see What is Service Quotas? and AWS service quotas.

Resource This deployment uses

VPCs

1

Elastic IP addresses

2

Auto Scaling groups

1

Application Load Balancers

1

t3.medium instances

1

m5.xlarge instances

4

EFS file systems

1

EFS mount targets

2

AWS Key Management Service (KMS) encryption keys

1

Secure Sockets Layer (SSL) certificates

1

Supported AWS Regions

For any Quick Start to work in a Region other than its default Region, all the services it deploys must be supported in that Region. You can launch a Quick Start in any Region and see if it works. If you get an error such as “Unrecognized resource type,” the Quick Start is not supported in that Region.

For an up-to-date list of AWS Regions and the AWS services they support, see AWS Regional Services.

Certain Regions are available on an opt-in basis. For more information, see Managing AWS Regions.

Amazon EC2 key pairs

Ensure that at least one Amazon EC2 key pair exists in your AWS account in the Region where you plan to deploy the Quick Start. Note the key-pair name because you will use it during deployment. To create a key pair, see Amazon EC2 key pairs and Linux instances.

For testing or proof-of-concept purposes, we recommend creating a new key pair instead of using one that’s already being used by a production instance.

IAM permissions

Before launching the Quick Start, you must sign in to the AWS Management Console with IAM permissions for the resources that the templates deploy. The AdministratorAccess managed policy within IAM provides sufficient permissions, although your organization may choose to use a custom policy with more restrictions. For more information, see AWS managed policies for job functions.

Prepare your Dell Boomi account

Ensure your Dell Boomi account has at least one available Enterprise Molecule license. Ensure you have a valid Account ID, Installation Token, API Key, or Username/Password.

Deployment options

This Quick Start provides two deployment options:

  • Deploy Molecule into a new VPC (end-to-end deployment). This option builds a new AWS environment consisting of the VPC, subnets, NAT gateways, security groups, bastion hosts, and other infrastructure components. It then deploys Molecule into this new VPC.

  • Deploy Molecule into an existing VPC. This option provisions Molecule in your existing AWS infrastructure.

The Quick Start provides separate templates for these options. It also lets you configure Classless Inter-Domain Routing (CIDR) blocks, instance types, and Molecule settings, as discussed later in this guide.

Authentication

In addition to the two deployment options, there are two authentication options for deployment.

  • Deploy with Account ID, Username, API Key, and Installation Token

  • Deploy with authorized Account ID, Username, and Password (Not MFA compatible)

You will need to choose one method or the other. If you are unsure of how to create an Installation Token or API Token/Key, see Creating an Installation Token in this guide for steps or contact your administrator.

Deployment steps

Sign in to your AWS account

  1. Sign in to your AWS account at https://aws.amazon.com with an IAM user role that has the necessary permissions. For details, see Planning the deployment earlier in this guide.

  2. Make sure that your AWS account is configured correctly, as discussed in the Technical requirements section.

Launch the Quick Start

You are responsible for the cost of the AWS services used while running this Quick Start reference deployment. There is no additional cost for using this Quick Start. For full details, see the pricing pages for each AWS service used by this Quick Start. Prices are subject to change.
  1. Sign in to your AWS account, and choose one of the following options to launch the AWS CloudFormation template. For help with choosing an option, see deployment options earlier in this guide.

Deploy Molecule into a new VPC on AWS

Deploy Molecule into an existing VPC on AWS

If you’re deploying Molecule into an existing VPC, make sure that your VPC has two private subnets in different Availability Zones for the workload instances, and that the subnets aren’t shared. This Quick Start doesn’t support shared subnets. These subnets require NAT gateways in their route tables, to allow the instances to download packages and software without exposing them to the internet.

Also, make sure that the domain name option in the DHCP options is configured, as explained in DHCP options sets. You provide your VPC settings when you launch the Quick Start.

Each deployment takes about 1 hour to complete.

  1. Check the AWS Region that’s displayed in the upper-right corner of the navigation bar, and change it if necessary. This is where the network infrastructure for Molecule will be built. The template is launched in the us-east-1 Region by default.

  1. On the Create stack page, keep the default setting for the template URL, and then choose Next.

  2. On the Specify stack details page, change the stack name if needed. Review the parameters for the template. Provide values for the parameters that require input. For all other parameters, review the default settings and customize them as necessary.

+ In the following tables, parameters are listed by category and described separately for the deployment options. When you finish reviewing and customizing the parameters, choose Next.

+ NOTE: Unless you are customizing the Quick Start templates for your own deployment projects, keep the default settings for the parameters Quick Start S3 bucket name, Quick Start S3 bucket Region, and Quick Start S3 key prefix. Changing these settings automatically updates code references to point to a new Quick Start location. For more information, see the AWS Quick Start Contributor’s Guide.

+

Launch into a new VPC

Table 1. Network configuration
Parameter label (name) Default value Description

Availability Zones (AvailabilityZones)

Requires input

List of Availability Zones to use for the subnets in the VPC. This deployment uses two Availability Zones, and the logical order of your selections is preserved.

VPC CIDR (VPCCIDR)

10.0.0.0/16

The CIDR block for the VPC.

Public subnet 1 CIDR (PublicSubnet1CIDR)

10.0.32.0/24

The CIDR block used for the public subnet located in Availability Zone 1.

Public subnet 2 CIDR (PublicSubnet2CIDR)

10.0.64.0/24

The CIDR block used for the public subnet located in Availability Zone 2.

Private subnet 1 CIDR (PrivateSubnet1CIDR)

10.0.128.0/24

The CIDR block used for the private subnet located in Availability Zone 1.

Private subnet 2 CIDR (PrivateSubnet2CIDR)

10.0.192.0/24

The CIDR block used for the private subnet located in Availability Zone 2.

Allowed external access CIDR (RemoteAccessCIDR)

Requires input

The CIDR IP range that is permitted to access the instances. We recommend that you set this value to a trusted IP range.

Table 2. Amazon EC2 configuration
Parameter label (name) Default value Description

SSH key name (KeyPairName)

Requires input

A public/private key pair, which allows you to connect securely to your instance after it launches.

Volume size for Boomi instances (MoleculeEBSVolume)

100

The size of the Amazon EBS volume attached to the Molecule instances. Size range is 1 GiB - 16 TiB.

Table 3. Boomi Molecule node sizing
Parameter label (name) Default value Description

Molecule node type (NodeInstanceType)

m5.xlarge

The Boomi host instance type.

Table 4. Boomi Molecule configuration
Parameter label (name) Default value Description

Molecule cluster name (MoleculeClusterName)

molecule1

The name for your Boomi Molecule cluster.

Molecule local path (MoleculeLocalPath)

/opt/molecule/local/

The local Path for the Molecule installation.

Molecule local temp directory (MoleculeLocalTemp)

/mnt/tmp

The local temporary path for the Molecule installation.

Boomi account ID (BoomiAccountID)

Requires input

The Boomi account ID that you want to associate with the new Molecule cluster.

Boomi user name (BoomiUsername)

Requires input

The email account associated with the Boomi account.

Boomi password (BoomiPassword)

Blank string

The password associated with the Boomi account.

Boomi MFA API token (BoomiInstallToken)

Blank string

An MFA API token generated by your Dell Boomi Administrator.

Molecule shared directory (MoleculeSharedDir)

/mnt/molecule

A shared directory for the EFS volume that the Molecules will mount.

Load Balancer listener port (LBListenerPort)

9093

The listener port of the Load Balancer.

Private ALB (PrivateALB)

false

The ALB can be placed in the Private subnets. Choose either 'yes' or 'no'

DeployALB (DeployALB)

true

Do you wish to deploy the ALB entirely? Choose either 'true' or 'false'

Table 5. Amazon EFS configuration
Parameter label (name) Default value Description

EFS encryption (EFSEncryption)

true

EFS volumes can be encrypted. Choose either "yes" or "no".

EFS performance mode (EFSPerformanceMode)

generalPurpose

The performance mode for the EFS volume.

EFS throughput mode (EFSThroughputMode)

bursting

The throughput mode for the EFS volume.

EFS provisioned throughput (EFSProvisionedThroughput)

10

The provisioned throughput value for the EFS volume.

Table 6. DNS or SSL configuration
Parameter label (name) Default value Description

Molecule FQDN (MoleculeFQDN)

Blank string

The fully qualified domain name for the Boomi Molecule cluster. Use with 'HostedZoneID' if you are not using SSL.

Route 53 hosted zone ID (HostedZoneID)

Blank string

Route 53 Hosted Zone ID of the domain name. Used in conjunction with a 'MoleculeFQDN'.

SSL certificate ARN (SSLCertificateArn)

Blank string

The ARN of the SSL certificate to use for the load balancer. Use 'SSLCertificateArn' if you are not using 'MoleculeFQDN' and 'HostedZoneID'.

Table 7. AWS Quick Start configuration
Parameter label (name) Default value Description

Quick Start S3 bucket name (QSS3BucketName)

aws-quickstart

S3 bucket name for the Quick Start assets. This string can include numbers, lowercase letters, uppercase letters, and hyphens (-). It cannot start or end with a hyphen (-).

Quick Start S3 bucket region (QSS3BucketRegion)

us-east-1

The AWS Region where the Quick Start S3 bucket (QSS3BucketName) is hosted. When using your own bucket, you must specify this value.

Quick Start S3 key prefix (QSS3KeyPrefix)

quickstart-boomi-molecule/

S3 key prefix for the Quick Start assets. Quick Start key prefix can include numbers, lowercase letters, uppercase letters, hyphens (-), and forward slash (/).

Launch into an existing VPC

Table 8. Network configuration
Parameter label (name) Default value Description

VPC ID (VPCID)

Requires input

The ID of your existing VPC.

Public subnet 1 ID (PublicSubnet1ID)

Blank string

The ID of the public subnet in Availability Zone 1 in your existing VPC.

Public subnet 2 ID (PublicSubnet2ID)

Blank string

The ID of the public subnet in Availability Zone 2 in your existing VPC.

Private subnet 1 ID (PrivateSubnet1ID)

Requires input

The ID of the private subnet in Availability Zone 1 in your existing VPC.

Private subnet 2 ID (PrivateSubnet2ID)

Requires input

The ID of the private subnet in Availability Zone 2 in your existing VPC.

Bastion security group ID (BastionSecurityGroupID)

Blank string

The ID of the bastion security group in your existing VPC. Used to provide access to the molecule (e.g., sg-1a2b3c4d).

Table 9. Amazon EC2 configuration
Parameter label (name) Default value Description

SSH key name (KeyPairName)

Requires input

Key name for access to EC2 instances.

Volume size for Boomi instances (MoleculeEBSVolume)

100

The size of the Amazon EBS volume attached to the Molecule instances. Size range is 1 GiB - 16 TiB (size listed in GiB).

Table 10. Boomi Molecule node sizing
Parameter label (name) Default value Description

Molecule node instance type (NodeInstanceType)

m5.xlarge

The Boomi host instance type.

Table 11. Boomi Molecule configuration
Parameter label (name) Default value Description

Molecule cluster name (MoleculeClusterName)

molecule1

The name for the Boomi Molecule cluster.

Molecule local path (MoleculeLocalPath)

/opt/molecule/local/

The local path for the Molecule installation.

Molecule local temp directory (MoleculeLocalTemp)

/mnt/tmp

The local temporary path for the Molecule installation.

Boomi account ID (BoomiAccountID)

Requires input

The Dell Boomi account ID that you want to associate with the new Molecule cluster.

Boomi user name (BoomiUsername)

Requires input

The email account associated with the Dell Boomi account.

Boomi password (BoomiPassword)

Blank string

The password associated with the Dell Boomi account.

Boomi MFA API token (BoomiInstallToken)

Blank string

A Boomi Install Token generated from within the AtomSphere console.

Load Balancer listener port (LBListenerPort)

9093

The port of the LB Listener.

Molecule shared directory (MoleculeSharedDir)

/mnt/molecule

A shared directory for Molecules.

Private ALB (PrivateALB)

false

The ALB can be placed in the Private subnets. 'DeployALB' takes precedence. Choose either 'true' or 'false

DeployALB (DeployALB)

true

Do you wish to deploy the ALB entirely? Choose either 'true' or 'false'

Table 12. Amazon EFS configuration
Parameter label (name) Default value Description

EFS encryption (EFSEncryption)

true

EFS volumes can be encrypted. Choose either "yes" or "no".

EFS performance mode (EFSPerformanceMode)

generalPurpose

The performance mode for the EFS volume.

EFS throughput mode (EFSThroughputMode)

bursting

The throughput mode for the EFS volume.

EFS provisioned throughput (EFSProvisionedThroughput)

10

The provisioned throughput value for the EFS volume.

Table 13. SSL configuration
Parameter label (name) Default value Description

SSL certificate ARN (SSLCertificateArn)

Blank string

The SSL Certificate ID used with the load balancer.

Table 14. AWS Quick Start configuration
Parameter label (name) Default value Description

Quick Start S3 bucket name (QSS3BucketName)

aws-quickstart

S3 bucket name for the Quick Start assets. This string can include numbers, lowercase letters, uppercase letters, and hyphens (-). It cannot start or end with a hyphen (-).

Quick Start S3 key prefix (QSS3KeyPrefix)

quickstart-boomi-molecule/

S3 key prefix for the Quick Start assets. Quick Start key prefix can include numbers, lowercase letters, uppercase letters, hyphens (-), and forward slash (/).

+ . On the Configure stack options page, you can specify tags (key-value pairs) for resources in your stack and set advanced options. When you finish, choose Next. . On the Review page, review and confirm the template settings. Under Capabilities, select the two check boxes to acknowledge that the template creates IAM resources and might require the ability to automatically expand macros. . Choose Create stack to deploy the stack. . Monitor the status of the stack. When the status is CREATE_COMPLETE, the Molecule deployment is ready. . To view the created resources, see the values displayed in the Outputs tab for the stack.

Test the deployment

To view the Molecule in the Dell Boomi AtomSphere platform, log in to your Dell Boomi account, navigate to the Manage drop-down menu, and choose Atom Management. The newly created Amazon EC2 instance Molecule cluster will be displayed.

image
Figure 2. Dell Boomi Dashboard with an unattached AWS-managed Molecule Cluster

You can then attach the Molecules to any environment you have staged and deploy workloads to that Molecule cluster. By Default the molecule you deployed will be under ‘Unattached Atoms’. When you click on ‘Atom Information’ you will see an option to attach it to an environment.

Security

This Quick Start deploys a bastion host and a Dell Boomi Molecule cluster into an AWS VPC. The bastion host is the only means of accessing the Dell Boomi Molecule cluster at a command-line level. The Dell Boomi Molecule cluster is deployed into private subnets and cannot be reached through the internet. The Boomi Molecule cluster communicates through a NAT Gateway for updates and patches, and it communicates through the public-facing Classic Load Balancer to communicate with the Dell Boomi AtomSphere platform.

Other useful information

Performance monitoring

Monitoring the CPU, network, and Amazon Elastic Block Store (Amazon EBS) performance of your AWS Dell Boomi Molecule cluster is done through CloudWatch metrics.

CPU and network performance are measured in utilization, network in and out, network packets in and out, and system status checks.

Amazon EBS volume performance is measured in read and write throughput, average read and write size, read and write bandwidth, read and write latency, and volume idle time.

Amazon EFS reports metrics to CloudWatch and can be monitored there. Metrics include client connections, data read and data write bytes, and IO percent limits.

Creating an installation token

Administrators can create an installation token without having to share login credentials for an Atom/Molecule installation. To create an installation token, do the following:

  1. Go to Manage > Atom Management.

  2. Choose +New > Molecule.

  3. On the Build page, choose the Welcome tab.

  4. Under the Create heading, choose Molecule.

  5. Choose Security Options.

  6. In the Token Valid for field, select the length of time the token is valid (30 minutes to 24 hours).

  7. Click Generate Token.

image
Figure 3. Molecule Setup

Creating an API token

Administrators can create a long-lived API token without having to share login credentials for an Atom/Molecule installation. To create an user API token, do the following:

  1. Choose Settings > Account Information and Setup.

  2. Choose the AtomSphere API Tokens tab.

  3. Choose Add New Token.

  1. Enter a unique name for the token.

image
Figure 4. New AtomSphere API Token
  1. Click Generate Token.

  2. Choose Copy to copy the token string to the clipboard without exiting. When you are ready to exit, click Copy to Clipboard & Close to copy the token string and exit the dialog.

image
Figure 5. Copying the token string

Copy the token key value to a secure location. It is recommended that you treat tokens with the same level of security as you would a password. If you lose it, you will have to generate a new token and revoke the old one.

FAQ

Q. I encountered a CREATE_FAILED error when I launched the Quick Start.

A. If AWS CloudFormation fails to create the stack, we recommend that you relaunch the template with Rollback on failure set to No. (This setting is under Advanced in the AWS CloudFormation console, Options page.) With this setting, the stack’s state is retained and the instance is left running, so you can troubleshoot the issue. (For Windows, look at the log files in %ProgramFiles%\Amazon\EC2ConfigService and C:\cfn\log.)

When you set Rollback on failure to Disabled, you continue to incur AWS charges for this stack. Please make sure to delete the stack when you finish troubleshooting.

For additional information, see Troubleshooting AWS CloudFormation on the AWS website.

Q. I encountered a size limitation error when I deployed the AWS CloudFormation templates.

A. We recommend that you launch the Quick Start templates from the links in this guide or from another S3 bucket. If you deploy the templates from a local copy on your computer or from a location other than an S3 bucket, you might encounter template size limitations. For more information about AWS CloudFormation quotas, see AWS CloudFormation quotas.

Customer responsibility

After you successfully deploy this Quick Start, confirm that your resources and services are updated and configured — including any required patches — to meet your security and other needs. For more information, see the AWS Shared Responsibility Model.

Send us feedback

To post feedback, submit feature ideas, or report bugs, use the Issues section of the GitHub repository for this Quick Start. To submit code, see the Quick Start Contributor’s Guide.

Quick Start reference deployments

GitHub repository

Visit our GitHub repository to download the templates and scripts for this Quick Start, to post your comments, and to share your customizations with others.


Notices

This document is provided for informational purposes only. It represents AWS’s current product offerings and practices as of the date of issue of this document, which are subject to change without notice. Customers are responsible for making their own independent assessment of the information in this document and any use of AWS’s products or services, each of which is provided “as is” without warranty of any kind, whether expressed or implied. This document does not create any warranties, representations, contractual commitments, conditions, or assurances from AWS, its affiliates, suppliers, or licensors. The responsibilities and liabilities of AWS to its customers are controlled by AWS agreements, and this document is not part of, nor does it modify, any agreement between AWS and its customers.

The software included with this paper is licensed under the Apache License, version 2.0 (the "License"). You may not use this file except in compliance with the License. A copy of the License is located at http://aws.amazon.com/apache2.0/ or in the accompanying "license" file. This code is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either expressed or implied. See the License for specific language governing permissions and limitations.